11843637

DHCP RELAY-BASED STEERING LOGIC FOR POLICY ENFORCEMENT ON IoT DEVICES

PublishedDecember 12, 2023
Assigneenot available in USPTO data we have
Technical Abstract

Patent Claims
19 claims

Legal claims defining the scope of protection, as filed with the USPTO.

2

2. The system of claim 1, wherein the steering logic is further configured to send the MAC addresses, the IP addresses, the information about the network segment, or the combination thereof to the device classification logic.

3

3. The system of claim 2, wherein the device classification logic is configured to use the MAC addresses, the IP addresses, the information about the network segment, or the combination thereof to categorize the special-purpose devices to one of a plurality of special-purpose device categories.

4

4. The system of claim 3, wherein the plurality of special-purpose device categories includes an Enterprise Internet of Things (EIoT) device category, an operational technology (OT) device category, an Internet of Medical Things (IoMT) device category, other IoT device category, or a combination thereof.

5

5. The system of claim 3, wherein the device classification logic is further configured to communicate the categorization, manufacturing information, software information, functional information, or a combination thereof to the steering logic as part of the positive determination.

6

6. The system of claim 5, wherein the steering logic is further configured to communicate the categorization, the manufacturing information, the software information, the functional information, or the combination thereof to the inline secure forwarder.

7

7. The system of claim 6, wherein the inline secure forwarder is further configured to communicate the categorization, the manufacturing information, the software information, the functional information, or the combination thereof to the policy enforcement point in conjunction with the outbound network traffic.

8

8. The system of claim 7, wherein the policy enforcement point is configured to use the categorization, the manufacturing information, the software information, the functional information, or the combination thereof to enforce one or more policies on the outbound network traffic.

9

9. The system of claim 8, wherein the policy enforcement point is further configured to classify the outbound network traffic as benign, policy-conforming, or a combination thereof based on the enforcement of the one or more policies.

10

10. The system of claim 9, wherein, based on the outbound network traffic being classified as benign, policy-conforming, or the combination thereof, the policy enforcement point is further configured to send the outbound network traffic to one or more out-of-network destinations intended by the special-purpose devices.

11

11. The system of claim 10, wherein the out-of-network destinations include cloud applications.

12

12. The system of claim 11, wherein the out-of-network destinations include web applications, websites, or a combination thereof.

13

13. The system of claim 8, wherein the policy enforcement point is further configured to classify the outbound network traffic as malicious, policy-non-conforming, or a combination thereof based on the enforcement of the one or more policies.

14

14. The system of claim 2, wherein the device classification logic is further configured to use the MAC addresses, the IP addresses, the information about the network segment, or the combination thereof to determine manufacturing information about the special-purpose devices.

15

15. The system of claim 14, wherein the manufacturing information identifies manufacturers of the special-purpose devices.

16

16. The system of claim 2, wherein the device classification logic is further configured to use the MAC addresses, the IP addresses, the information about the network segment, or the combination thereof to determine software information about the special-purpose devices.

17

17. The system of claim 16, wherein the software information identifies applications, application versions running on the special-purpose devices, or a combination thereof.

18

18. The system of claim 2, wherein the device classification logic is further configured to use the MAC addresses, the IP addresses, the information about the network segment, or the combination thereof to determine functional information about the special-purpose devices.

19

19. The system of claim 18, wherein the functional information identifies functions of the special-purpose devices.

20

20. The system of claim 19, wherein the functions include medical functions, premise security functions, scanning functions, sensing functions, or a combination thereof.

Patent Metadata

Filing Date

Unknown

Publication Date

December 12, 2023

Inventors

David Tze-Si WU
Siying YANG
Krishna NARAYANASWAMY

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “DHCP RELAY-BASED STEERING LOGIC FOR POLICY ENFORCEMENT ON IoT DEVICES” (11843637). https://patentable.app/patents/11843637

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.